LiveActive security incident?Get immediate response
CVE Record

CVE-2022-4986: Hirschmann EagleSDV Denial of Service via TLS

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

HighCVSS 8.7Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This is an availability risk for Hirschmann EagleSDV devices. A vulnerable version can crash while establishing TLS sessions using TLS 1.0 or TLS 1.1, interrupting service. The issue is network-reachable and does not require authentication, so exposed devices should be prioritized for vendor-guided remediation.

Executive priority

Treat this as a high-priority operational resilience issue where EagleSDV devices support production or safety-adjacent networks. Prioritize exposed or broadly reachable devices first, then complete firmware validation through normal industrial change controls.

Technical view

CVE-2022-4986 is a CWE-400 denial-of-service flaw in Hirschmann EagleSDV 05.4.01 prior to 05.4.02. The crash occurs during TLS session establishment when TLS 1.0 or TLS 1.1 is used. The CVSS 4.0 score is 8.7, driven by network access, low complexity, no privileges, no user interaction, and high availability impact.

Likely exposure

Likely exposure is limited to organizations running Hirschmann EagleSDV 05.4.01 or earlier affected builds with TLS services reachable over a network. Risk is higher where management or operational interfaces are reachable from broad internal networks or untrusted zones.

Exploitation context

The provided sources and KEV status do not show confirmed active exploitation. The vulnerability appears straightforward to trigger because it is network-accessible and unauthenticated, but the source bundle does not provide public exploitation evidence beyond the described denial-of-service condition.

Researcher notes

The source bundle describes a TLS 1.0/1.1 session-establishment crash and CVSS 4.0 availability impact only. It does not establish confidentiality or integrity impact, active exploitation, or a workaround beyond vendor remediation. The affected-version metadata appears inconsistent, so verify against Belden’s advisory.

Mitigation direction

  • Upgrade affected EagleSDV devices to version 05.4.02 or vendor-recommended later releases.
  • Review Belden advisory BSECV-2022-08 for exact affected versions and operational guidance.
  • Restrict network access to EagleSDV TLS services to trusted management segments.
  • Review whether TLS 1.0 and TLS 1.1 can be disabled per vendor guidance.
  • Monitor impacted environments for unexpected EagleSDV crashes or service interruptions.

Validation and detection

  • Inventory Hirschmann EagleSDV devices and record firmware versions.
  • Confirm whether any device runs 05.4.01 or another vendor-listed affected version.
  • Identify reachable TLS services and their network exposure boundaries.
  • Check change records for upgrade to 05.4.02 or later vendor-approved firmware.
  • Review device logs for crash patterns during TLS session establishment.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-400: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-4986 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.7 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.7CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NVulnCheck
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6VulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

8.7High
CVSS 4.0 vector shape for CVE-2022-4986Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
BeldenHirschmann EagleSDV05.4.02, 0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-400 · source CWE mapping

Uncontrolled Resource Consumption

Uncontrolled Resource Consumption represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.